First published: Wed Jul 15 2020(Updated: )
Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Harbor | <2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2020-13788.
The severity of CVE-2020-13788 is medium with a severity value of 4.3.
CVE-2020-13788 is a vulnerability in Harbor prior to 2.0.1 which allows Server-Side Request Forgery (SSRF) with the limitation that an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.
Harbor versions up to and excluding 2.0.1 are affected by CVE-2020-13788.
To fix CVE-2020-13788, it is recommended to update to Harbor version 2.0.1 or later.